VulnerabilityModified
CVE-2025-45769
php-jwt v6.11.0 was discovered to contain weak encryption.
MEDIUM 6.5EPSS 0.14%
Does this matter?
Lower severity and a low EPSS score (0.14%). Track it; it rarely justifies an emergency change on its own.
Description
php-jwt v6.11.0 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.14% probability · 3th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-326
- Affected
- google/firebase php-jwt
- Source
- cve@mitre.org
References
- https://gist.github.com/ZupeiNie/83756316c4c24fe97a50176a92608db3Third Party Advisory
- https://github.com/advisories/GHSA-2x45-7fc3-mxwq
- https://github.com/firebaseProduct
- https://github.com/firebase/php-jwtProduct
- https://github.com/firebase/php-jwt/issues/620
- https://github.com/firebase/php-jwt/pull/613
- https://github.com/firebase/php-jwt/releases/tag/v7.0.0
- https://github.com/github/advisory-database/pull/6954
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.